Holehe Field Guide

A practical companion guide to using Holehe well: how to read a report, when to retry, how to handle ambiguous results, and which third-party OSINT tools pair naturally with it. This isn't a separate product, it's a workflow page for getting more out of the Holehe you already use.

1. Reading a Holehe report

Every Holehe report has the same anatomy: a list of sites, each tagged Found, Not Found or Rate-limited, grouped into categories.

  • Found, the site's public sign-up or password-recovery flow confirms an account exists for that email
  • Not Found, the site returned a clear "no account" signal
  • Rate-limited, the site blocked or throttled the probe; not a verdict

A clean report still has noise: treat rate-limited entries as "come back later," not as proof of absence.

2. Quick-look heuristics

A few patterns to recognise at a glance:

  • Heavy social hits, no developer hits, likely a consumer account, not a technical one.
  • Heavy developer hits (GitHub, GitLab, Stack Overflow, npm), likely a real engineer; expect a coherent username trail.
  • Only one or two hits, the address is either niche-use or recently created. Cross-check with HaveIBeenPwned.
  • Zero hits, frequently a disposable or relay address (HIDE/Apple/ DuckDuckGo Email Protection / SimpleLogin).
  • Mostly shopping and music, light, personal use; the person is less likely to be technically inclined.

3. When to retry a scan

Rerun the same email a few hours later if:

  • Several big platforms came back rate-limited
  • You see an unusually low Found count for an old address
  • You scanned during a peak hour on a known sensitive provider

Holehe rotates outbound IPs server-side, so a second run picks up a fresh egress and often resolves the rate-limited entries.

4. Companion OSINT tools

Holehe is one piece of a wider email-OSINT toolkit. The tools below answer the questions Holehe deliberately leaves alone.

Breach & reputation

  • HaveIBeenPwned, known data breaches that include the address
  • DeHashed / IntelX, broader leak coverage (paid)
  • EmailRep.io, reputation score and abuse signals

Going deep on one account

  • GHunt, public Google profile for a Gmail address
  • EpieOS, web wrapper around several email-OSINT techniques

Username pivots

  • Sherlock, classic handle-hunter across hundreds of sites
  • Maigret, richer cousin of Sherlock with deeper metadata
  • WhatsMyName, community ruleset, very fast

Domain & infrastructure

  • whois / RDAP, registrant data for custom domains
  • crt.sh, certificate transparency, useful for subdomain discovery

5. A sample workflow

  1. Holehe scan of the email → list of registered platforms.
  2. HaveIBeenPwned + EmailRep on the same email → breach and reputation context.
  3. If Gmail, run GHunt for the Google profile.
  4. Pick the strongest usernames from the Holehe report → Sherlock or Maigret.
  5. If custom domain → whois + crt.sh to map the infrastructure.
  6. Document with timestamps and source URLs.

Each tool feeds the next. Holehe is the spark that makes the rest of the chain useful.

6. Where to go next